DevMan is a ransomware family and financially motivated extortion operation that emerged publicly in early 2025. Its operators initially participated in ransomware affiliate programs including Qilin, DragonForce, APOS, and RansomHub before establishing their own ransomware-as-a-service platform. The platform provides affiliates with payload generation, victim management, negotiation, team coordination, and earnings oversight. DevMan supports Windows, Linux, and VMware ESXi lockers and has targeted organizations across Asia, Africa, Europe, and North America, including technology, healthcare, financial services, professional services, government, and industrial sectors.
Early DevMan payloads reuse DragonForce code derived from Conti, while another analyzed sample exhibits substantial code overlap with Mamona. Windows variants support configurable local and network-share encryption, multithreaded execution, scheduled starts, host or subnet targeting, and credential-assisted domain spreading. Observed behaviors include network-share discovery, SMB-based lateral movement, termination of security processes and services, deletion of volume shadow copies, event-log clearing, and optional self-deletion. Some variants use Windows Restart Manager to access files held open by other processes. Encryption implementations vary: an analyzed variant derives HC-256 key material through Curve25519 ECDH and Blake2, while a later locker uses ChaCha20-Poly1305. Partial encryption of larger files reduces execution time.
DevMan operations use double extortion, combining file encryption with data theft and threats of publication on leak sites. Intrusions involve compromised credentials or exposed remote services, followed by reconnaissance and deployment across endpoints and network-accessible resources. Data theft is an operational behavior rather than a demonstrated capability of every locker: one analyzed Windows sample contained no identified exfiltration functionality despite its ransom note claiming stolen data. The affiliate program explicitly encourages targeting critical infrastructure.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The DevMan ransomware report lists CVE-2024-3400 under MITRE CONTEXT → Exploitation Vulnerabilities.
The DevMan ransomware report lists CVE-2023-23397 under MITRE CONTEXT → Exploitation Vulnerabilities.
The DevMan ransomware report lists CVE-2024-43451 under MITRE CONTEXT → Exploitation Vulnerabilities.
The DevMan ransomware report lists CVE-2025-31324 under MITRE CONTEXT → Exploitation Vulnerabilities.
4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
DevMan has become more independent and claimed to use their own ransomware, eponymously named “DevMan”.
The operators of the DevMan ransomware-as-a-service (RaaS) scheme are maintaining a dedicated web platform that offers affiliates the ability to build payloads, oversee earnings, and manage various aspects related to victims.
Devman declined by 70%, from 82 victims to 25. The ransomware’s operator “Tramp”, a former Conti and Black Basta affiliate, was added to Interpol’s wanted list in January 2026.
“Security researchers have reportedly identified Devman ransomware payloads that are build on DragonForce infrastructure.”
24 distinct techniques documented for this family, organized by ATT&CK tactic.
MITRE Technique Names: ... Windows Management Instrumentation
MITRE Technique Names: ... Command and Scripting Interpreter
An analysis of the Windows version has identified functions related to privilege checking to determine if it's running as an administrator, security-control impairment, process and service termination, recovery inhibition, event log clearing, local and network-share discovery, lateral movement, multi-threaded encryption, ransom-note creation, and optional self-deletion.
An analysis of the Windows version has identified functions related to privilege checking to determine if it's running as an administrator, security-control impairment, process and service termination, recovery inhibition, event log clearing, local and network-share discovery, lateral movement, multi-threaded encryption, ransom-note creation, and optional self-deletion.
An analysis of the Windows version has identified functions related to privilege checking to determine if it's running as an administrator, security-control impairment, process and service termination, recovery inhibition, event log clearing, local and network-share discovery, lateral movement, multi-threaded encryption, ransom-note creation, and optional self-deletion.
An analysis of the Windows version has identified functions related to privilege checking to determine if it's running as an administrator, security-control impairment, process and service termination, recovery inhibition, event log clearing, local and network-share discovery, lateral movement, multi-threaded encryption, ransom-note creation, and optional self-deletion.
The latest version of the portal allows affiliates to create a locker for Windows, ESXi, or Linux. An analysis of the Windows version has identified functions related to privilege checking to determine if it's running as an administrator, security-control impairment, process and service termination, recovery inhibition, event log clearing, local and network-share discovery, lateral movement, multi-threaded encryption, ransom-note creation, and optional self-deletion.
An analysis of the Windows version has identified functions related to privilege checking to determine if it's running as an administrator, security-control impairment, process and service termination, recovery inhibition, event log clearing, local and network-share discovery, lateral movement, multi-threaded encryption, ransom-note creation, and optional self-deletion.
An analysis of the Windows version has identified functions related to privilege checking to determine if it's running as an administrator, security-control impairment, process and service termination, recovery inhibition, event log clearing, local and network-share discovery, lateral movement, multi-threaded encryption, ransom-note creation, and optional self-deletion.
An analysis of the Windows version has identified functions related to privilege checking to determine if it's running as an administrator, security-control impairment, process and service termination, recovery inhibition, event log clearing, local and network-share discovery, lateral movement, multi-threaded encryption, ransom-note creation, and optional self-deletion. | The operators of the DevMan ransomware-as-a-service (RaaS) scheme are maintaining a dedicated web platform that offers affiliates the ability to build payloads, oversee earnings, and manage various aspects related to victims.
An analysis of the Windows version has identified functions related to privilege checking to determine if it's running as an administrator, security-control impairment, process and service termination, recovery inhibition, event log clearing, local and network-share discovery, lateral movement, multi-threaded encryption, ransom-note creation, and optional self-deletion.
An analysis of the Windows version has identified functions related to privilege checking to determine if it's running as an administrator, security-control impairment, process and service termination, recovery inhibition, event log clearing, local and network-share discovery, lateral movement, multi-threaded encryption, ransom-note creation, and optional self-deletion.
10 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
16 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A ransomware-as-a-service operation with a dedicated affiliate portal for payload building, victim management, earnings, team coordination, and payout handling. Its Windows locker includes privilege checks, security-control impairment, process and service termination, recovery inhibition, event log clearing, local and network-share discovery, lateral movement, multi-threaded encryption, ransom-note creation, and optional self-deletion. It encrypts files using ChaCha20-Poly1305 and also offers Windows, ESXi, and Linux lockers, with a separate SCADA-focused encryptor mentioned for critical infrastructure attacks.
Devman is a ransomware family linked in reporting to Vect through shared builder strings, matching DM-prefixed lateral movement task naming, and similar ransom notes. The content suggests possible operator continuity, rebranding, or code overlap.
A ransomware family linked in reporting to Vect through shared strings, ransom-note similarities, and matching lateral movement task naming conventions. The content suggests possible operator continuity, rebranding, or code overlap.
A ransomware operation whose activity collapsed after pressure on its operator and shutdown of its leak sites; it had links to a former Conti and Black Basta affiliate.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.